97 lines
3.1 KiB
HCL
97 lines
3.1 KiB
HCL
#
|
|
# DMARC reports service: parsedmarc, OpenSearch and OpenSearch Dashboards on
|
|
# one VM.
|
|
#
|
|
# Sizing and service ports belong to the service, so they have defaults here.
|
|
# The address on the main private network does not: it is part of the address
|
|
# plan of the project, and it is passed in by the caller.
|
|
#
|
|
|
|
variable "dmarc_reports_data" {
|
|
description = "Instance, volume and ports of the DMARC reports service. m1.large is RAM 8 - VCPUs 4"
|
|
type = object({
|
|
name = optional(string, "opensearch-dmarc")
|
|
description = optional(string, "DMARC reports: parsedmarc, OpenSearch and OpenSearch Dashboards")
|
|
flavor = optional(string, "m1.large")
|
|
boot_vol_size = optional(number, 20)
|
|
# OpenSearch data directory. SSD, as every volume that holds an index
|
|
vol_data_name = optional(string, "opensearch-dmarc-data")
|
|
vol_data_size = optional(number, 50)
|
|
vol_data_device = optional(string, "/dev/vdb")
|
|
volume_type = optional(string, "CephSSD")
|
|
# OpenSearch Dashboards, the only port the load balancers reach. It
|
|
# terminates TLS itself with the certificate of the internal CA
|
|
service_ports = optional(list(number), [5601])
|
|
})
|
|
default = {}
|
|
}
|
|
|
|
# Part of the address plan of the project: no default on purpose
|
|
variable "dmarc_reports_main_ip" {
|
|
type = string
|
|
description = "Address of the instance on the main private network"
|
|
}
|
|
|
|
# Data that comes from the network/DNS and project setup workspaces
|
|
variable "main_private_network_id" {
|
|
type = string
|
|
description = "ID of the main private network of the project"
|
|
}
|
|
|
|
variable "main_private_subnet_id" {
|
|
type = string
|
|
description = "ID of the main private subnet of the project"
|
|
}
|
|
|
|
variable "default_security_group_id" {
|
|
type = string
|
|
description = "ID of the 'default_for_all' security group of the project"
|
|
}
|
|
|
|
variable "haproxy_l7_ip" {
|
|
type = list(string)
|
|
description = "Addresses of the L7 HAPROXY load balancers, the only ones allowed to reach the service"
|
|
}
|
|
|
|
variable "availability_zone" {
|
|
type = string
|
|
description = "Availability zone hint of the instance"
|
|
}
|
|
|
|
variable "image" {
|
|
description = "Image of the instance: uuid and cloud-init user data file"
|
|
type = object({
|
|
uuid = string
|
|
user_data_file = string
|
|
})
|
|
}
|
|
|
|
variable "ssh_key_name" {
|
|
type = string
|
|
description = "Name of the SSH key pair injected by cloud-init"
|
|
}
|
|
|
|
# DNS. The A record on the main network address is always created; the public
|
|
# name is a CNAME of the load balancer that publishes the service
|
|
variable "dns_zone_id" {
|
|
type = string
|
|
description = "ID of the DNS zone of the project"
|
|
}
|
|
|
|
variable "dns_zone_name" {
|
|
type = string
|
|
description = "Name of the DNS zone of the project, with the trailing dot"
|
|
}
|
|
|
|
variable "dmarc_reports_public_name" {
|
|
type = string
|
|
default = "dmarc"
|
|
description = "Left part of the public name, a CNAME of the load balancer. Empty means no record"
|
|
}
|
|
|
|
variable "dmarc_reports_cname_target" {
|
|
type = string
|
|
default = ""
|
|
description = "Target of the CNAME, usually the name of the main load balancer, with the trailing dot"
|
|
}
|